QID 981807
QID 981807: Java (maven) Security Update for org.apache.zeppelin:zeppelin (GHSA-9x2h-hvg6-4r5p)
In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentication.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-9x2h-hvg6-4r5p for updates pertaining to this vulnerability.
Vendor References
- GHSA-9x2h-hvg6-4r5p -
github.com/advisories/GHSA-9x2h-hvg6-4r5p
CVEs related to QID 981807
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9x2h-hvg6-4r5p | org.apache.zeppelin:zeppelin |
|